CVE Database /
CVE-2026-7798
CVE · Medium
CVE-2026-7798 — FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution [fluent-crm] < 3.0.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-7798
|
FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution [fluent-crm] < 3.0.0 |
Server-Side Request Forgery (SSRF) |
Medium
5.4
|
< 3.0.0
|
3.0.0 |
2026-05-21 |
—
|
CVE-2026-7798
The FluentCRM plugin for WordPress contains a security flaw affecting all versions up to 2.9.87, specifically in how it handles the 'SubscribeURL' parameter. This issue allows unauthorized users to initiate web requests from the application itself, potentially allowing them to access or modify internal data. The vulnerability can be exploited if the site has never been configured for SES bounce handling, as this would prevent the plugin's authentication check from functioning correctly.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings